PT-2017-13083 · Open Networking Operating System · Onos

Publicado

2017-08-30

·

Atualizado

2022-05-13

·

CVE-2017-13763

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions ONOS versions 1.8.0 through 1.10.0
Description The issue is related to the lack of restriction on the amount of memory allocated, specifically due to the unlimited Netty payload size. This can lead to a potential denial of service, as seen in ONOS nodes timing out when attempting to connect to the cluster in a vm test cluster.
Recommendations For ONOS version 1.8.0, consider restricting the Netty payload size to prevent excessive memory allocation. For ONOS version 1.9.0, restrict the Netty payload size to minimize the risk of denial of service. For ONOS version 1.10.0, limit the Netty payload size to prevent potential service disruptions.

Correção

Allocation of Resources Without Limits

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-13763
GHSA-C6P7-VHW7-RC9W

Produtos afetados

Onos